Forcing users through Dansguardian and Squid Using IPTables

Posted on 2008-11-11
Last Modified: 2013-11-15
Hi i need to send my clients through dansguardian and squid without any configuration on the client machines.

i havent tested the following rules, i would like somebody to check over them beforehand. and point out what can be improved and where.

Thanks in advanced.

iptables -t nat -A PREROUTING -i eth1 -p tcp --dport 80 -j REDIRECT --to-port 8080

iptables -A INPUT -j ACCEPT -m state --state NEW,ESTABLISHED,RELATED -o eth1 -p tcp --dport 8080

iptables -A OUTPUT -j ACCEPT -m state --state NEW,ESTABLISHED,RELATED -o eth0 -p tcp --dport 80

iptables -A INPUT -j ACCPET -m state --state ESTABLISHED,RELATED -i eth0 -p tcp --sport 80

iptables -A OUTPUT -j ACCEPT -m state --state ESTABLISHED,RELATED -o eth1 -p tcp --sport 80

Open in new window

Question by:CNTPL89
    LVL 5

    Expert Comment

    It all looks good to me

    Author Comment

    i get an error on the second rule saying i cant use a -o on a input, i used -p instead, this doesnt work. any ideas?
    LVL 5

    Accepted Solution

    Right.. sorry I missed that.  The "-o" on the second line should be "-i".  You have the INPUT chain, as you should, but the "-o" specifies that traffic will be going out that interface.  It will not, it will be coming in to it from your workstations.

    Featured Post

    IT, Stop Being Called Into Every Meeting

    Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

    Join & Write a Comment

    If you use Debian 6 Squeeze and you are tired of looking at the childish graphical GDM login screen that is used by default, here's an easy way to change it. If you've already tried to change it you've probably discovered that none of the old met…
    The purpose of this article is to show how we can create Linux Mint virtual machine using Oracle Virtual Box. To install Linux Mint we have to download the ISO file from its website i.e. Once you open the link you will see …
    This video is in connection to the article "The case of a missing mobile phone (". It will help one to understand clearly the steps to track a lost android phone.
    Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

    734 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    22 Experts available now in Live!

    Get 1:1 Help Now